How a Non-Atomic Credential Rotation Let Attackers Take Over 76 Trivy Action Tags
A compromised-credential attack on Aquasecurity's Trivy scanner force-pushed malware into version tags across trivy-action and setup-trivy, exploiting the gap left by an earlier, incomplete rotation.